#304 Rust lane proposal — no execution authorized by this document. Priority: authored W1 (#301/#282/#288/#251), then #297 regression coverage on d89a655f's public/private seams. Current HEAD 0cea7d64; Rust tests/workflow edits remain dirty. Freeze a new source commit after static integration and #297 test authoring. #297 has production source but NO authored bootstrap_firewall regression module yet; do not run an empty filter and call it coverage. Pool: NEW .worktrees/hertz-304/target, exclusive to test/304-remote-friction. It is currently absent. No junction, external CARGO_TARGET_DIR, copying, takeover or use of protected hertz-294-sync-stages target. Existing Cargo registry download cache may be reused; compiled target is COLD. Record rustc -Vv, lockfile hash, profile/RUSTFLAGS, pool identity and exact compiled outputs. First bootstrap xtask compilation must be guarded externally before a prebuilt meter exists; thereafter claim through this tree's prebuilt xtask with label hertz-304-w1-297. This requires an explicit cold-bootstrap exception to local-lane.py's warm-pool precondition, NOT silently relaxing that driver. Release via prebuilt xtask at lane end; no target deletion. Capacity [engineering estimate, not measured guarantee]: 30–50 GiB cold target+linker/incremental growth for the selected project binaries and shared dependencies; request 64 GiB aggregate volume-growth ceiling, comprising up to60 GiB build/link/cache plus4 GiB fixture/temp/evidence margin. Reserve32 GiB; admission>=96 GiB (103,079,215,104 bytes), stop if free<=32 GiB (34,359,738,368) OR start_free-current_free>=64 GiB (68,719,476,736). Monitor through builds, inventory, execution and cleanup. Any error/unreadable sample refuses. Latest script-lane end sample191,755,583,488 bytes is historical, not allocation. The earlier warm4–8 GiB estimate does NOT apply. If the cold estimate proves insufficient, stop and report; no unapproved retry/widening. Expected duration [estimate]: cold selected compilation25–50 minutes, selected tests5–15 minutes; outer build deadline60 minutes total, execution deadline20 minutes total, with existing per-test timeouts unchanged. No concurrent producers; build jobs2. One attempt per producer, no automatic retry. A failure retains actual exit, failure-time capacity and cleanup census, and stops later execution unless a separately approved independent evidence axis is explicitly selected. Exact build/test binary set: 1. xtask binary for pool verbs and documentation producer-guard tests (W0 companion only; CLI-reference generation is NOT requested). 2. spt-daemon library unit-test binary: filters webserve::tests:: and shellchan::tests::vocab_check_bounds_ops_and_args; #297 bootstrap_firewall tests only after authored and nonempty inventory verified. 3. spt binary unit-test binary: rc::tests::viewer_byte_detach_keeps_controller_and_child, rc::tests::viewer_event_detach_keeps_controller_and_child (Windows), rc::tests::detach_keybind_semantics, rc::tests::detach_prefix_spans_chunks, rc::tests::key_event_step_detach_sm (Windows); #297 serveverb regression selections only after authored/nonempty inventory. 4. spt-daemon integration binary docs_server_e2e. 5. spt-daemon integration binary webserve_e2e. 6. spt integration binary webserve_cross_node_e2e: a_peers_url_is_served_by_its_owner_through_the_local_listener. 7. spt integration binary attach_link_push_e2e: attachment_frames_reach_a_linked_shell_through_the_real_daemon. Prerequisite fixture executables: real spt binary; mock-adapter mock-session (additional fixture requirements must be statically enumerated before build, never discovered by launching stale artifacts). No workspace test sweep, clippy/all-targets, doctests, two-host rungs, golden run, release build or Linux build included. xtask CLI-reference tests may be a later independent selection; do not count their source as exercised merely because xtask compiled. Inventory: use nextest list JSON with exact package/binary/test expressions; retain selected cases and executing binary paths, reject empty/malformed lists. Execute the same expressions, single heavy-broker-PTY group, preserve existing nextest profile limits/timeouts. Separate compilation from execution; complete pre-run census before releasing any fixture. Isolation prerequisites: SPT_INSTALL_NO_FIREWALL=1 inherited by every spawned CLI/daemon; no actual Windows Firewall/netsh/PowerShell rule calls, no Linux firewall manager operations. #297 policy tests must use a hermetic command-execution seam that cannot fall through to real host commands. Private same-volume SPT_HOME and TMP/TEMP/TMPDIR/RUNNER_TEMP, identity variables scrubbed, OS-assigned advisory ports. Real local-daemon W1 fixtures are NOT claimed loopback-only solely because SPT_HOME is private: statically inspect/explicitly disable relay/discovery and prevent fleet peer/interface interaction before execution. For any fixture needing real interfaces or discovery, request a separate isolated-host allocation rather than assuming this one authorizes it. Existing exposed LAN bootstrap listener is operator state and untouched. Before each phase: quiet golden meter with positive control; builder and scoped image+birth/command/temp census; pool ownership and capacity. After every producer, success/failure/timeout alike: retain actual exit, raw output, monotonic timings, capacity observations, bounded cleanup of owned process identities, post-cleanup scoped census. No PID-only kill or blanket image kill. Process/access uncertainty must be reported, not claimed as universal clearance. Remaining gates before execution: Doyle GO for cold pool/capacity/duration, final exact source SHA+selection inventory, missing #297 test authoring, concrete per-fixture network isolation, source-compilation proof and fixture binary prerequisites. Public #297 seam is bootstrap_firewall::{verify,reconcile,cleanup,is_clean}; CLI delayed/competing helper and stopped-listener cleanup behavior must be tested without host firewall mutation. Fresh firewalld absence must leave bootstrap available/admission UNVERIFIED/no writes (including no reload/runtime-to-permanent/latent permanent policy); existing owned-policy reconciliation is separate.